|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2024-3044: libreoffice: unchecked script execution in graphic on-click binding | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | SMASH SMASH <smash_bz> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | IN_PROGRESS --- | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | carlos.lopez, martin.schreiner, stoyan.manolov |
| Version: | unspecified | Flags: | stoyan.manolov:
needinfo?
(martin.schreiner) |
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/405761/ | ||
| Whiteboard: | CVSSv3.1:SUSE:CVE-2024-3044:7.1:(AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N) | ||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
SMASH SMASH
2024-05-15 10:25:44 UTC
Just an update here, I'm submitting 24.2.4.1 to SLE-12-SP5, SLE-15-SP5 and SLE-15-SP6. This update already contains the patch to fix this issue. I'll post all SR links here. I'm reassigning this to the security team, as I've submitted 24.2.4.2 to all currently supported codestreams, and that release includes this fix, as per LibreOffice's own documentation: https://www.libreoffice.org/about-us/security/advisories/CVE-2024-3044 SUSE-SU-2024:2258-1: An update that solves one vulnerability and has one security fix can now be installed. Category: security (important) Bug References: 1224279, 1224309 CVE References: CVE-2024-3044 Maintenance Incident: [SUSE:Maintenance:34419](https://smelt.suse.de/incident/34419/) Sources used: SUSE Linux Enterprise Software Development Kit 12 SP5 (src): libreoffice-24.2.4.2-48.59.3 SUSE Linux Enterprise Workstation Extension 12 12-SP5 (src): libreoffice-24.2.4.2-48.59.3 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2024:2257-1: An update that solves one vulnerability and has one security fix can now be installed. Category: security (important) Bug References: 1224279, 1224309 CVE References: CVE-2024-3044 Maintenance Incident: [SUSE:Maintenance:34418](https://smelt.suse.de/incident/34418/) Sources used: openSUSE Leap 15.5 (src): libreoffice-24.2.4.2-150500.20.6.5 openSUSE Leap 15.6 (src): libreoffice-24.2.4.2-150500.20.6.5 SUSE Package Hub 15 15-SP5 (src): libreoffice-24.2.4.2-150500.20.6.5 SUSE Package Hub 15 15-SP6 (src): libreoffice-24.2.4.2-150500.20.6.5 SUSE Linux Enterprise Workstation Extension 15 SP5 (src): libreoffice-24.2.4.2-150500.20.6.5 SUSE Linux Enterprise Workstation Extension 15 SP6 (src): libreoffice-24.2.4.2-150500.20.6.5 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. |